[Kernel-packages] [Bug 1375416] [NEW] fix some small kmemleaks in apparmor 3 RC1

2014-09-29 Thread Jamie Strandboge
Public bug reported: There are some small kmemleaks that should be addressed. ** Affects: linux (Ubuntu) Importance: High Assignee: Tyler Hicks (tyhicks) Status: Confirmed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed t

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with apparmor 3.0 RC1 kernel

2014-09-29 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Milestone: None => ubuntu-14.10 ** Changed in: linux (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310

[Kernel-packages] [Bug 1375416] Re: fix some small kmemleaks in apparmor 3 RC1

2014-09-29 Thread Jamie Strandboge
** Tags added: ota-2 -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1375416 Title: fix some small kmemleaks in apparmor 3 RC1 Status in “linux” package in Ubuntu: Confirmed Bug descr

[Kernel-packages] [Bug 1375416] Re: fix some small kmemleaks in apparmor 3 RC1

2014-09-29 Thread Jamie Strandboge
** Tags added: apparmor -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1375416 Title: fix some small kmemleaks in apparmor 3 RC1 Status in “linux” package in Ubuntu: Confirmed Bug de

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with apparmor 3.0 RC1 kernel

2014-10-01 Thread Jamie Strandboge
I can confirm that reverting the patch John Johansen mentioned makes docker.io work as well as in previous releases. We will have this fixed before 14.10 release. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bug

[Kernel-packages] [Bug 1373070] Re: full fix for disconnected path (paths)

2014-10-02 Thread Jamie Strandboge
I'm going to need to add attach_disconnected to the cups profile as a temporary workaround. When this bug is fixed, we need to undo that. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1373

[Kernel-packages] [Bug 1373070] Re: full fix for disconnected path (paths)

2014-10-02 Thread Jamie Strandboge
Here is another: Sep 10 09:06:00 callisto kernel: audit: type=1400 audit(1410332760.203:112): apparmor="DENIED" operation="connect" info="Failed name lookup - disconnected path" error=-13 profile="/usr/sbin/cupsd" name="run/dbus/system_bus_socket" pid=3608 comm="cupsd" requested_mask="rw" denied

[Kernel-packages] [Bug 1373070] Re: full fix for disconnected path (paths)

2014-10-02 Thread Jamie Strandboge
** Changed in: cups (Ubuntu) Status: New => In Progress ** Changed in: cups (Ubuntu) Importance: Undecided => High ** Changed in: cups (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Kernel

[Kernel-packages] [Bug 1375416] Re: AppArmor leaks kernel memory during profile reloads

2014-10-02 Thread Jamie Strandboge
I'm curious how far back this goes. Does it exist in trusty? precise? lucid? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1375416 Title: AppArmor leaks kernel memory during profile rel

[Kernel-packages] [Bug 1375416] Re: AppArmor leaks kernel memory during profile reloads

2014-10-03 Thread Jamie Strandboge
I'm going to reduce the priority of this to Medium since it exists on trusty and noone has reported it yet. We still need to fix it, but there are likely others things we want to get to first. ** Changed in: linux (Ubuntu) Importance: High => Medium ** Changed in: linux (Ubuntu) Milestone:

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with apparmor 3.0 RC1 kernel

2014-10-07 Thread Jamie Strandboge
FYI, this should be in a new kernel soon: https://lists.ubuntu.com/archives/kernel-team/2014-October/049001.html -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310 Title: docker.io d

[Kernel-packages] [Bug 1208988] Re: AppArmor no longer mediates access to path-based AF_UNIX socket files

2014-10-08 Thread Jamie Strandboge
Marking the apparmor task as 'fixed' since this is available in the upstream beta tarballs. ** Changed in: apparmor Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-maguro in Ubuntu. https

[Kernel-packages] [Bug 1327687] Re: AppArmor Regression #1236455 by #1298611

2014-10-09 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New => Fix Released ** Changed in: linux (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1

[Kernel-packages] [Bug 1357103] Re: apparmor denied a golang build inside a container

2014-10-09 Thread Jamie Strandboge
Does the kernel in comment #4 address this issue? ** No longer affects: apparmor (Ubuntu) ** Changed in: linux (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.

[Kernel-packages] [Bug 1357103] Re: apparmor denied a golang build inside a container

2014-10-10 Thread Jamie Strandboge
I'm going to mark as Fix Released for now then. Please open a new bug if you see this again. ** Changed in: linux (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://

[Kernel-packages] [Bug 1350947] Re: apparmor: no working rule to allow making a mount private

2014-10-10 Thread Jamie Strandboge
** Changed in: apparmor Importance: Undecided => Medium ** Changed in: apparmor Status: New => Confirmed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1350947 Title: apparmor

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-04 Thread Jamie Strandboge
** Description changed: Background: kernel and apparmor userspace updates to support abstract, anonymous and fine-grained netlink socket mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times.

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-04 Thread Jamie Strandboge
** Tags added: rtm14 touch-2014-09-11 -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1362199 Title: [FFe] apparmor abstract, anonymous and netlink socket mediation Status in “apparmor”

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-05 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Importance: Undecided => Critical ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to li

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-05 Thread Jamie Strandboge
isc-dhcp (4.2.4-7ubuntu14) utopic; urgency=medium * debian/apparmor-profile.dhclient: add file_inherit inet{,6} dgram rules for child profiles ** Changed in: isc-dhcp (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Kern

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-08 Thread Jamie Strandboge
** Description changed: Background: kernel and apparmor userspace updates to support abstract, anonymous and fine-grained netlink socket mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times. + +

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-08 Thread Jamie Strandboge
** Description changed: Background: kernel and apparmor userspace updates to support abstract, anonymous and fine-grained netlink socket mediation. These packages are listed in one bug because they are related, but the FFes may be granted and the uploads may happen at different times.

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-08 Thread Jamie Strandboge
1) old kernel and new userspace - this is well tested and ready to land now 2) new kernel and old userspace 3) new kernel and new userspace - these are tested, but need more testing on the kernel side. We are finalizing the kernel and will have these in place for kernel pull requests Ah, I did n

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-08 Thread Jamie Strandboge
FYI, when booting new userspace with old kernel, the parser will output something like this: Warning from profile /usr/lib/telepathy/telepathy-ofono (/etc/apparmor.d/usr.lib.telepathy): downgrading extended network unix socket rule to generic network rule -- You received this bug notification

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-17 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Importance: Undecided => Critical ** Changed in: linux (Ubuntu) Importance: Critical => High -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1362199 Tit

[Kernel-packages] [Bug 1371310] [NEW] docker.io doesn't work with 3.0 RC1 kernel

2014-09-18 Thread Jamie Strandboge
Public bug reported: Steps to reproduce (from https://wiki.ubuntu.com/Process/Merges/TestPlans/AppArmor): 1. sudo apt-get install docker.io # 1.2.0~dfsg1-1 2. sudo docker pull ubuntu:trusty 3. sudo docker run ubuntu:trusty uptime 2014/09/18 15:48:48 Error response from daemon: Cannot start cont

[Kernel-packages] [Bug 1362199] Re: [FFe] apparmor abstract, anonymous and netlink socket mediation

2014-09-18 Thread Jamie Strandboge
** Also affects: linux-mako (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-goldfish (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-flo (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-manta (Ubuntu) Importanc

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with 3.0 RC1 kernel

2014-09-18 Thread Jamie Strandboge
Installing auditd does not help. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310 Title: docker.io doesn't work with 3.0 RC1 kernel Status in “apparmor” package in Ubuntu: New S

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with 3.0 RC1 kernel

2014-09-18 Thread Jamie Strandboge
Adding the following to /etc/apparmor.d/docker does not help: audit unix, audit signal, audit ptrace, change_profile -> *, -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310 Ti

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with 3.0 RC1 kernel

2014-09-18 Thread Jamie Strandboge
The target profile is loaded: $ sudo aa-status|grep docker docker-default I tried this on the 3.16.0-9.14 and 3.16.0-16.22 distro kernels. The 'docker run' command succeeds. If I do this: $ sudo docker run -i -t ubuntu:trusty /bin/sh I can verify the container is launched under confinement he

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with 3.0 RC1 kernel

2014-09-18 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Undecided => High ** Changed in: linux (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310 Tit

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with 3.0 RC1 kernel

2014-09-19 Thread Jamie Strandboge
After discussing on IRC, we will revert the patch enabling stricter requirements to restore previous behavior while we investigate the best approach to resolve the issue properly. ** Changed in: linux (Ubuntu) Status: Confirmed => Triaged ** Changed in: apparmor (Ubuntu) Status: New

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with apparmor 3.0 RC1 kernel

2014-09-19 Thread Jamie Strandboge
** Description changed: Steps to reproduce (from https://wiki.ubuntu.com/Process/Merges/TestPlans/AppArmor): 1. sudo apt-get install docker.io # 1.2.0~dfsg1-1 2. sudo docker pull ubuntu:trusty 3. sudo docker run ubuntu:trusty uptime 2014/09/18 15:48:48 Error response from daem

[Kernel-packages] [Bug 1373070] [NEW] full fix for disconnected path

2014-09-23 Thread Jamie Strandboge
Public bug reported: With the apparmor 3 RC1 upload, there is an incomplete bug fix for disconnected paths. This bug is to track that work. This denial may be related: Sep 23 10:10:50 localhost kernel: [40262.517799] audit: type=1400 audit(1411485050.722:2862): apparmor="DENIED" operation="sendm

[Kernel-packages] [Bug 1371310] Re: docker.io doesn't work with apparmor 3.0 RC1 kernel

2014-09-23 Thread Jamie Strandboge
** Tags added: apparmor -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1371310 Title: docker.io doesn't work with apparmor 3.0 RC1 kernel Status in “apparmor” package in Ubuntu: Inval

[Kernel-packages] [Bug 1373176] Re: unix_socket_pathname.sh confined client dgram test fails

2014-09-24 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Importance: Undecided => Medium -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1373176 Title: unix_socket_pathname.sh confined client dgram test fails S

[Kernel-packages] [Bug 1373174] Re: unix_socket_pathname.sh confined server dgram test fails

2014-09-24 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Importance: High => Medium -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1373174 Title: unix_socket_pathname.sh confined server dgram test fails Status

[Kernel-packages] [Bug 1387214] Re: file corruption on touch images in rw portions of the filesystem

2014-11-06 Thread Jamie Strandboge
** Tags added: rtm14 ** Package changed: linux (Ubuntu) => system-image (Ubuntu) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1387214 Title: file corruption on touch images in rw port

[Kernel-packages] [Bug 1390592] [NEW] 'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker

2014-11-07 Thread Jamie Strandboge
Public bug reported: I was helping a docker user out in #apparmor on OFTC and I think we found a kernel bug. Filing this on behalf of the user. The user added the following to the base abstraction then reloaded policy: ptrace peer=@{profile_name}, but had denials like this: apparmor="DENIED"

[Kernel-packages] [Bug 1390592] Re: 'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker

2014-11-07 Thread Jamie Strandboge
** Description changed: I was helping a docker user out in #apparmor on OFTC and I think we - found a kernel bug. Filing this on behalf of the user. + found a kernel bug in the 14.04 kernel. - The user added the following to the base abstraction then reloaded policy: - ptrace peer=@{profile

[Kernel-packages] [Bug 1390592] Re: 'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker

2014-11-07 Thread Jamie Strandboge
** Description changed: I was helping a docker user out in #apparmor on OFTC and I think we found a kernel bug in the 14.04 kernel. - $ cat /proc/version_signature + $ cat /proc/version_signature Ubuntu 3.13.0-37.64-generic 3.13.11.7 Steps to reproduce: 1. adjust /etc/apparmor.d/a

[Kernel-packages] [Bug 1390546] Re: kernel-level crash when debugging from inside Docker

2014-11-07 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1390546 Title: kernel-level crash when debugging from inside Do

[Kernel-packages] [Bug 1390592] Re: 'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker

2014-11-10 Thread Jamie Strandboge
Per Tyler, this is fixed in r2456. In 14.04, add-decimal-interp.patch should be removed in favor of this patch. ** No longer affects: linux (Ubuntu) ** Also affects: apparmor (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Status: Confirmed =>

[Kernel-packages] [Bug 921000] Re: no logging if using non-existent child profile

2014-10-15 Thread Jamie Strandboge
** Tags added: aa-kernel -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/921000 Title: no logging if using non-existent child profile Status in AppArmor Linux application security framew

[Kernel-packages] [Bug 921000] Re: no logging if using non-existent child profile

2014-10-23 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Assignee: John Johansen (jjohansen) => (unassigned) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/921000 Title: no logging if using non-existent child

[Kernel-packages] [Bug 484786] Re: Better support for btrfs snapshots

2014-10-23 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Importance: Low => Medium ** Changed in: apparmor (Ubuntu) Status: Confirmed => Triaged ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged -- You received this bug no

[Kernel-packages] [Bug 1384746] Re: Support multiple versions of AppArmor policy cache files

2014-10-23 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed => Triaged -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1384746 Title: Support multiple versions of AppArmor policy cache file

[Kernel-packages] [Bug 1384735] Re: Mediate anonymous pipes

2014-10-23 Thread Jamie Strandboge
** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New ** Changed in: apparmor (Ubuntu) Status: New => Confirmed ** Changed in: apparmor (Ubuntu) Importance: Undecided => Medium ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Chan

[Kernel-packages] [Bug 484786] Re: Better support for btrfs snapshots

2014-10-23 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Importance: Undecided => Medium -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/484786 Title: Better support for btrfs snapshots Status in AppArmor Linux

[Kernel-packages] [Bug 1379535] Re: namespace stacking

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: linux (Ubuntu) Status: Triaged => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Critical ** Tags added: aa-kernel

[Kernel-packages] [Bug 1379536] Re: Coarse-grained kernel keyring mediation

2014-10-23 Thread Jamie Strandboge
** Changed in: apparmor Status: Triaged => In Progress ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: apparmor (Ubuntu) Status: Confirmed => Triaged ** Changed in: linux (Ubuntu

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: apparmor (Ubuntu) Status: Confirmed => Triaged ** Changed in: linux (Ubuntu) Importance: Undecided => High ** Tags added: aa-kernel -

[Kernel-packages] [Bug 969299] Re: Don't require use of mediate_deleted with LXC (was: apparmor prevents dpkg-divert and localedef from working in a container)

2014-10-23 Thread Jamie Strandboge
** Tags added: aa-kernel ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu Precise) Status: New => Won't Fix ** Changed in: linux (Ubuntu) Importance: Undecided => Medium ** Changed in: linux (Ubuntu) Status: New => Confirm

[Kernel-packages] [Bug 1045985] Re: support environment filtering

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Low ** Tags added: aa-kernel -- You received this bug notification because you are a member of Ker

[Kernel-packages] [Bug 970647] Re: Denials due to "deleted" are not being logged

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Low ** Changed in: apparmor (Ubuntu) Assignee: John Johansen (jjohansen) => (unassigned) ** Ch

[Kernel-packages] [Bug 1306781] Re: Kernel to userspace communication is needed to notify trusted helpers of profile changes

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: linux (Ubuntu) Importance: Undecided => Low ** Tags added: aa-kernel -- You received this bug notification because you are a member of Kerne

[Kernel-packages] [Bug 1379537] Re: Fine-grained kernel keyring mediation

2014-10-23 Thread Jamie Strandboge
** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: linux (Ubuntu) Status: Triaged => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Low ** Tags added: aa-kernel -- Y

[Kernel-packages] [Bug 1379538] Re: Better support for docker.io

2014-10-23 Thread Jamie Strandboge
** Tags added: aa-kernel ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ker

[Kernel-packages] [Bug 1370218] Re: Fine-grained shm mediation (confined applications need access to /run/shm/shmfd*)

2014-10-23 Thread Jamie Strandboge
** Tags added: aa-kernel ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Triaged ** Changed in: linux (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Kerne

[Kernel-packages] [Bug 1379541] Re: Named sockets should use 'unix' rules instead of 'file'

2014-10-23 Thread Jamie Strandboge
** Tags added: aa-kernel aa-parser ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a mem

[Kernel-packages] [Bug 1387214] [NEW] file corruption on touch images in rw portions of the filesystem

2014-10-29 Thread Jamie Strandboge
Public bug reported: Symptoms are that cache files in /var/cache/apparmor and profiles in /var/lib/apparmor/profiles are sometimes corrupted after a reboot. We've already fixed several bugs in the apparmor and click-apparmor and made both more robust in the face of corruption, but we've still not

[Kernel-packages] [Bug 1387214] Re: file corruption on touch images in rw portions of the filesystem

2014-10-29 Thread Jamie Strandboge
Added application-confinement and apparmor tags since this bug affects both and it will be easier to find. ** Description changed: Symptoms are that cache files in /var/cache/apparmor and profiles in /var/lib/apparmor/profiles are sometimes corrupted after a reboot. We've already fixed seve

[Kernel-packages] [Bug 1387522] Re: package linux-image-generic 3.16.0.24.25 failed to install/upgrade: package linux-image-generic is already installed and configured

2014-10-31 Thread Jamie Strandboge
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-meta in Ubuntu. https://bugs.launchpad.net/bugs/1387522 Title: package linux-image-generic 3.16.0.24.25 failed to install/

[Kernel-packages] [Bug 1425398] Re: Apparmor uses rsyslogd profile for different processes - utopic HWE

2015-05-21 Thread Jamie Strandboge
Simon, that is a different issue unrelated to this update. It is being tracked in bug #1373070. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-lts-utopic in Ubuntu. https://bugs.launchpad.net/bugs/1425398 Title: Apparmor uses rsy

[Kernel-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2015-04-13 Thread Jamie Strandboge
** Description changed: With the following use of overlayfs, we get a disconnected path: $ cat ./profile #include profile foo {   #include   capability sys_admin,   capability sys_chroot,   mount,   pivot_root, } $ cat ./overlay.c #include #include #include

[Kernel-packages] [Bug 1384342] Re: kernel messages intel_crtc_wait_for_pending_flips correlate to compiz hang

2015-02-11 Thread Jamie Strandboge
FYI, I filed duplicate bug #1413238 and it has all the info on my hardware. I don't know what codename of the chipset I have is, but the laptop is a Lenova x201s. System/Details says "Graphics: Intel® Ironlake Mobile" and my traceback has "ironlake_crtc_disable" in it, so I'm concerned that the pat

[Kernel-packages] [Bug 1292234] Re: qcow2 image corruption on non-extent filesystems (ext3)

2015-02-11 Thread Jamie Strandboge
Woohoo! *Huge* thanks. This was a tricky one :) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1292234 Title: qcow2 image corruption on non-extent filesystems (ext3) Status in linux pac

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2015-02-12 Thread Jamie Strandboge
** Changed in: apparmor Status: Confirmed => In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/796588 Title: Fine-grained network mediation Status in AppArmor Linux appl

[Kernel-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2015-02-24 Thread Jamie Strandboge
** Description changed: With the following use of overlayfs, we get a disconnected path: $ cat ./profile #include profile foo {   #include   capability sys_admin,   capability sys_chroot,   mount,   pivot_root, } $ cat ./overlay.c #include #include #include

[Kernel-packages] [Bug 1465322] [NEW] regression: "df: `/sys/kernel/debug': Function not implemented" with 3.2.0-85.122

2015-06-15 Thread Jamie Strandboge
Public bug reported: $ cat /proc/version_signature Ubuntu 3.2.0-84.121-generic 3.2.68 $ df | head -3 Filesystem 1K-blocksUsed Available Use% Mounted on /dev/vda17481832 4262872 2838904 61% / udev 371920 4371916 1% /dev $ cat /proc/version_signature Ubu

[Kernel-packages] [Bug 1465322] Re: regression: "df: `/sys/kernel/debug': Function not implemented" with 3.2.0-85.122

2015-06-15 Thread Jamie Strandboge
Marking as confirmed since I was able to reproduce on two different systems. ** Description changed: - $ cat /proc/version_signature + $ cat /proc/version_signature Ubuntu 3.2.0-84.121-generic 3.2.68 $ df | head -3 - Filesystem 1K-blocks Used Available Use% Mounted on - /dev/md

[Kernel-packages] [Bug 1465322] Re: regression: "df: `/sys/kernel/debug': Function not implemented" with 3.2.0-85.122

2015-06-15 Thread Jamie Strandboge
This works as advertised in an amd64 VM. $ cat /proc/version_signature Ubuntu 3.2.0-85.122~lp1465322-generic 3.2.69 $ df | head -3 Filesystem 1K-blocksUsed Available Use% Mounted on /dev/vda17481832 4264172 2837604 61% / udev 371924 4371920 1% /dev --

[Kernel-packages] [Bug 1465322] Re: regression: "df: `/sys/kernel/debug': Function not implemented" with 3.2.0-85.122

2015-06-16 Thread Jamie Strandboge
Reverting df438af seems to have fixed it. $ cat /proc/version_signature Ubuntu 3.2.0-86.123~lp1465322Commitdf438afReverted-generic 3.2.69 $ df | head -3 Filesystem 1K-blocksUsed Available Use% Mounted on /dev/vda17481832 4735296 2366480 67% / udev 371924 4

[Kernel-packages] [Bug 1465322] Re: regression: "df: `/sys/kernel/debug': Function not implemented" with 3.2.0-85.122

2015-06-24 Thread Jamie Strandboge
The kernel in precise-proposed fixes this for me. $ cat /proc/version_signature Ubuntu 3.2.0-87.125-generic 3.2.69 $ df | head -3 Filesystem 1K-blocksUsed Available Use% Mounted on /dev/vda17481832 5146416 1955360 73% / udev 371920 4371916 1% /dev --

[Kernel-packages] [Bug 1423810] Re: apparmor fd_inheritance regression test causes kernel to crash on touch kernel backports

2015-03-03 Thread Jamie Strandboge
Updated the summary since it said it was for krillin and the krillin task is being tracked in bug #1427825. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-manta in Ubuntu. https://bugs.launchpad.net/bugs/1423810 Title: apparmor f

[Kernel-packages] [Bug 1423810] Re: [krillin] apparmor fd_inheritance regression test causes kernel to crash

2015-03-03 Thread Jamie Strandboge
Bug is in the various kernels. apparmor task is to track getting the patch into the backports tree. ** Changed in: linux-flo (Ubuntu) Status: New => In Progress ** Changed in: linux-flo (Ubuntu) Importance: Undecided => Medium ** Changed in: linux-flo (Ubuntu) Assignee: (unassigne

[Kernel-packages] [Bug 1384342] Re: kernel messages intel_crtc_wait_for_pending_flips correlate to compiz hang

2015-03-10 Thread Jamie Strandboge
FYI, 14.10 is not a development release, it is a stable non-LTS release which therefore receives security updates and high impact bug fixes for 9 months. This kernel is also part of the hardware enablement stack for LTS releases which may help to prioritize bugs of this nature. As to whether this b

[Kernel-packages] [Bug 1408106] [NEW] allow defining the attach root for attach_disconnected

2015-01-06 Thread Jamie Strandboge
Public bug reported: With the following use of overlayfs, we get a disconnected path: $ cat ./profile #include profile foo {   #include   capability sys_admin,   capability sys_chroot,   mount,   pivot_root, } $ cat ./overlay.c #include #include #include #include #include #include #incl

[Kernel-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2015-01-08 Thread Jamie Strandboge
** Summary changed: - allow defining the attach root for attach_disconnected + attach_disconnected not sufficient for overlayfs -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1408106 Titl

[Kernel-packages] [Bug 1413238] [NEW] Intel i915 driver pauses and tracebacks

2015-01-21 Thread Jamie Strandboge
Public bug reported: On 14.10, X has been causing me all kinds of problems. It seems to most often happen after the screenlock has been on. When coming back from being locked, sometimes the system is unresponsive, but I can cajole it back to life by repeatedly going to a VT-- once I see a login pr

[Kernel-packages] [Bug 1413238] Re: Intel i915 driver pauses and tracebacks

2015-01-21 Thread Jamie Strandboge
This might be related to bug #1393089. ** Description changed: - On 14.10, X has been causing me all kinds of problems. It seems to most often happen after the screenlock has been on. When coming back from being locked, sometimes the system is unresponsive, but I can cajole it back to life by

[Kernel-packages] [Bug 1413238] Re: Intel i915 driver pauses and tracebacks

2015-01-22 Thread Jamie Strandboge
FYI, after coming back to my computer this morning, X was not having trouble. I'd like to see my system in a bad state again on 14.10 before retrying another kernel, cause I may have a potential other clue as to the problem (but don't want to cloud the issue now). Would running the current vivid d

[Kernel-packages] [Bug 1413238] Re: Intel i915 driver pauses and tracebacks

2015-01-22 Thread Jamie Strandboge
** Changed in: linux (Ubuntu) Status: Incomplete => New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1413238 Title: Intel i915 driver pauses and tracebacks Status in linux pac

[Kernel-packages] [Bug 1413238] Re: Intel i915 driver pauses and tracebacks

2015-01-26 Thread Jamie Strandboge
The vivid kernel did not help. In fact, under normal operation there are many weird visual artifacts (eg, blocks of lines). $ cat /proc/version_signature Ubuntu 3.18.0-9.10-generic 3.18.2 [15809.934345] [ cut here ] [15809.934379] WARNING: CPU: 2 PID: 1872 at /build/buil

[Kernel-packages] [Bug 1590391] Re: On ufw report MAC erroneous

2016-06-08 Thread Jamie Strandboge
Thank you for reporting a bug. The MAC in the log entry comes from the kernel and contains several pieces of information: the src MAC, the dst MAC and the TYPE. See http://logi.cc/en/2010/07/netfilter-log-format/ ** Information type changed from Private Security to Public ** Package changed: ufw

[Kernel-packages] [Bug 796588] Re: Fine-grained network mediation

2016-07-28 Thread Jamie Strandboge
FYI, this is a requirement for snapd, but it was deprioritized in favor of namespace stacking in support of LXD, upstreaming and other work in support of snappy (eg, gsettings mediation). A lot of work was done to support this, but the soonest it would be delivered given current priorities is 17.04

[Kernel-packages] [Bug 1621899] [NEW] System failed to suspend properly or resume

2016-09-09 Thread Jamie Strandboge
Public bug reported: I noticed this system failed to suspend properly and failed to resume. Closed the lid, the fans kept going. Opened the lid and lights were flashing indicating an error and had to hard reset. It had the following in the logs: Sep 9 07:43:19 ginny gnome-session[6351]: Tracebac

[Kernel-packages] [Bug 1621899] CRDA.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "CRDA.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737699/+files/CRDA.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1621899 Ti

[Kernel-packages] [Bug 1621899] IwConfig.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "IwConfig.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737701/+files/IwConfig.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/16

[Kernel-packages] [Bug 1621899] Lspci.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "Lspci.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737703/+files/Lspci.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1621899

[Kernel-packages] [Bug 1621899] Lsusb.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "Lsusb.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737704/+files/Lsusb.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1621899

[Kernel-packages] [Bug 1621899] ProcCpuinfo.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "ProcCpuinfo.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737705/+files/ProcCpuinfo.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1621899] ProcModules.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "ProcModules.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737708/+files/ProcModules.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1621899] ProcInterrupts.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "ProcInterrupts.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737707/+files/ProcInterrupts.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad

[Kernel-packages] [Bug 1621899] JournalErrors.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "JournalErrors.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737702/+files/JournalErrors.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.n

[Kernel-packages] [Bug 1621899] ProcEnviron.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "ProcEnviron.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737706/+files/ProcEnviron.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1621899] CurrentDmesg.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "CurrentDmesg.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737700/+files/CurrentDmesg.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net

[Kernel-packages] [Bug 1621899] WifiSyslog.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "WifiSyslog.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737712/+files/WifiSyslog.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bug

[Kernel-packages] [Bug 1621899] UdevDb.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "UdevDb.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737711/+files/UdevDb.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1621899

[Kernel-packages] [Bug 1621899] PulseList.txt

2016-09-09 Thread Jamie Strandboge
apport information ** Attachment added: "PulseList.txt" https://bugs.launchpad.net/bugs/1621899/+attachment/4737709/+files/PulseList.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/

<    1   2   3   4   5   6   7   8   >